Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ body:
id: version
attributes:
label: Brewlet version
placeholder: v0.4.0
placeholder: v0.5.0
validations:
required: true
- type: textarea
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/site-pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ jobs:
# registry pulls; the smoke script isolates saved registry credentials.
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: ./site/scripts/verify-release-artifacts.sh 0.4.0
run: ./site/scripts/verify-release-artifacts.sh 0.5.0

deploy:
needs: [release-smoke, site-contracts]
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -108,7 +108,7 @@ installs `brewlet` to `$HOME/.local/bin` by default. No Go toolchain or GitHub
authentication is required:

```bash
export BREWLET_VERSION="0.4.0"
export BREWLET_VERSION="0.5.0"
curl -fsSL https://brewlet.sh/install.sh | sh
export PATH="$HOME/.local/bin:$PATH"
brewlet version
Expand Down Expand Up @@ -160,7 +160,7 @@ Install the published chart on your disposable cluster:

```bash
helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \
--version 0.4.0 \
--version 0.5.0 \
--namespace brewlet \
--create-namespace \
--set provisioner.pools="{java-workers}" \
Expand Down
18 changes: 9 additions & 9 deletions docs/building-and-publishing.md
Original file line number Diff line number Diff line change
Expand Up @@ -157,7 +157,7 @@ exact packaged `BOOT-INF/lib/*.jar` entries, not a second dependency resolution:

```bash
# One-off: enable layering on the command line
mvn clean package sh.brewlet:brewlet-maven-plugin:0.4.0:push \
mvn clean package sh.brewlet:brewlet-maven-plugin:0.5.0:push \
-Dbrewlet.image=registry.example.com/team/app:1.4.2 \
-Dbrewlet.layered=true
```
Expand All @@ -166,7 +166,7 @@ mvn clean package sh.brewlet:brewlet-maven-plugin:0.4.0:push \
<plugin>
<groupId>sh.brewlet</groupId>
<artifactId>brewlet-maven-plugin</artifactId>
<version>0.4.0</version>
<version>0.5.0</version>
<configuration>
<image>registry.example.com/team/app:${project.version}</image>
<layered>true</layered> <!-- thin JAR + dependency layers -->
Expand Down Expand Up @@ -323,20 +323,20 @@ with override guidance instead of silently selecting the build machine's JDK.
See the [complete inference precedence](https://github.com/microsoft/brewlet/blob/main/maven-plugin/README.md#jdk-inference).

Download the released plugin JAR and POM from
the [GitHub release](https://github.com/microsoft/brewlet/releases/tag/v0.4.0) and
the [GitHub release](https://github.com/microsoft/brewlet/releases/tag/v0.5.0) and
install them once in your local Maven repository:

```bash
curl -fLO https://github.com/microsoft/brewlet/releases/download/v0.4.0/brewlet-maven-plugin-0.4.0.jar
curl -fLO https://github.com/microsoft/brewlet/releases/download/v0.4.0/brewlet-maven-plugin-0.4.0.pom
curl -fLO https://github.com/microsoft/brewlet/releases/download/v0.5.0/brewlet-maven-plugin-0.5.0.jar
curl -fLO https://github.com/microsoft/brewlet/releases/download/v0.5.0/brewlet-maven-plugin-0.5.0.pom
mvn org.apache.maven.plugins:maven-install-plugin:3.1.4:install-file \
-Dfile=brewlet-maven-plugin-0.4.0.jar \
-DpomFile=brewlet-maven-plugin-0.4.0.pom
-Dfile=brewlet-maven-plugin-0.5.0.jar \
-DpomFile=brewlet-maven-plugin-0.5.0.pom
```

```bash
# Build the fat JAR and push it as a Brewlet OCI artifact in one line:
mvn clean package sh.brewlet:brewlet-maven-plugin:0.4.0:push \
mvn clean package sh.brewlet:brewlet-maven-plugin:0.5.0:push \
-Dbrewlet.image=registry.example.com/team/app:1.4.2
```

Expand All @@ -346,7 +346,7 @@ Or configure publishing once in `pom.xml` and bind `push` to the lifecycle:
<plugin>
<groupId>sh.brewlet</groupId>
<artifactId>brewlet-maven-plugin</artifactId>
<version>0.4.0</version>
<version>0.5.0</version>
<configuration>
<image>registry.example.com/team/app:${project.version}</image>
<jdkFeature>21</jdkFeature>
Expand Down
4 changes: 2 additions & 2 deletions docs/cli-reference.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ export PATH="$HOME/.local/bin:$PATH"
brewlet version
```

The installer selects the latest release by default. Set `BREWLET_VERSION=0.4.0`
The installer selects the latest release by default. Set `BREWLET_VERSION=0.5.0`
to pin a release or `BREWLET_INSTALL_DIR=/custom/bin` to change the destination.
You can instead build the CLI with `make binaries` (producing `./bin/brewlet`).

Expand Down Expand Up @@ -337,7 +337,7 @@ Print the release version embedded in the binary:

```bash
brewlet version
# 0.4.0
# 0.5.0
```

Source builds without release linker flags print `dev`.
Expand Down
6 changes: 3 additions & 3 deletions docs/configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -113,7 +113,7 @@ provisioner:

```bash
helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \
--version 0.4.0 -f values-production.yaml
--version 0.5.0 -f values-production.yaml
```

> JDKs and launchers are always obtained **copy-from-image** from explicit,
Expand Down Expand Up @@ -208,7 +208,7 @@ When you install via Helm, the chart populates them for you.
| Flag | Default | Meaning |
|---|---|---|
| `--namespace` | `brewlet` | Namespace the provisioner DaemonSet is managed in. |
| `--provisioner-image` | `ghcr.io/microsoft/brewlet-node-provisioner:0.4.0` | Image the DaemonSet runs. |
| `--provisioner-image` | `ghcr.io/microsoft/brewlet-node-provisioner:0.1.0` | Image the DaemonSet runs. Published Helm charts override this with the release image digest. |
| `--allowed-source-mirror-hosts` | *(empty)* | Comma-separated exact destination registry hosts approved for NodeProfile runtime-source rewrites. Configure the same value on manager and admission; empty disables mirrors. |
| `--leader-elect` | `false` | Enable leader election for HA. |
| `--metrics-bind-address` | `0` | Metrics endpoint; `0` disables it. |
Expand All @@ -218,7 +218,7 @@ When you install via Helm, the chart populates them for you.

```bash
./bin/operator --namespace=brewlet \
--provisioner-image=ghcr.io/microsoft/brewlet-node-provisioner:0.4.0 \
--provisioner-image=ghcr.io/microsoft/brewlet-node-provisioner:0.5.0 \
--allowed-source-mirror-hosts=registry.internal.example.com
kubectl apply -f nodeprofile.yaml
```
Expand Down
8 changes: 4 additions & 4 deletions docs/getting-started.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,14 +33,14 @@ the matching release archive, and verifies its SHA-256 checksum before
installing it:

```bash
export BREWLET_VERSION="0.4.0"
export BREWLET_VERSION="0.5.0"
curl -fsSL https://brewlet.sh/install.sh | sh
export PATH="$HOME/.local/bin:$PATH"

brewlet version
```

The last command must print `0.4.0`.
The last command must print `0.5.0`.

Without `BREWLET_VERSION`, the installer selects the latest release. Set
`BREWLET_INSTALL_DIR` to choose a directory other than `$HOME/.local/bin`.
Expand Down Expand Up @@ -78,7 +78,7 @@ mkdir -p "$BREWLET_WORK"
brewlet version
```

The CLI reports the source build's version, which need not be `0.4.0`. Continue
The CLI reports the source build's version, which need not be `0.5.0`. Continue
at step 2 from this checkout.

## 2. Build the example
Expand Down Expand Up @@ -163,7 +163,7 @@ and Linux; executing the bundle with `runc` is a Linux node operation.

## What you proved

- Brewlet came from the checksum-verified v0.4.0 release or your optional
- Brewlet came from the checksum-verified v0.5.0 release or your optional
source build.
- The application payload contains only the JAR and launch metadata.
- A node-resident JDK can run the packaged application directly.
Expand Down
10 changes: 5 additions & 5 deletions docs/installation.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ section.

Brewlet publishes version-aligned multi-architecture component images and an OCI
Helm chart. A published chart records the **immutable digest** of each component
image it was built against, so installing chart `0.4.0` resolves
image it was built against, so installing chart `0.5.0` resolves
`ghcr.io/microsoft/brewlet-operator@sha256:…` rather than a tag that could later
be repointed. Charts packaged from a source checkout have no recorded digests and
fall back to the shared `images.tag`.
Expand Down Expand Up @@ -113,7 +113,7 @@ store, verify everything for a release in one step:
```bash
git clone https://github.com/microsoft/brewlet.git
cd brewlet
./scripts/verify-release-provenance.sh 0.4.0
./scripts/verify-release-provenance.sh 0.5.0
```

The script checks that each image, the chart, and every release asset was built
Expand All @@ -125,12 +125,12 @@ To verify a single artifact directly:

```bash
# A component image, straight from the registry.
gh attestation verify oci://ghcr.io/microsoft/brewlet-operator:0.4.0 \
gh attestation verify oci://ghcr.io/microsoft/brewlet-operator:0.5.0 \
--repo microsoft/brewlet \
--signer-workflow microsoft/brewlet/.github/workflows/release.yml

# A downloaded CLI archive.
gh attestation verify brewlet_0.4.0_linux_amd64.tar.gz \
gh attestation verify brewlet_0.5.0_linux_amd64.tar.gz \
--repo microsoft/brewlet \
--signer-workflow microsoft/brewlet/.github/workflows/release.yml
```
Expand Down Expand Up @@ -183,7 +183,7 @@ Install the released chart:

```bash
helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \
--version 0.4.0 \
--version 0.5.0 \
--namespace brewlet \
--create-namespace \
--set provisioner.pools="{java-workers}" \
Expand Down
4 changes: 2 additions & 2 deletions docs/managed-dependency-bundles.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,7 +90,7 @@ owned by the application team.
<plugin>
<groupId>sh.brewlet</groupId>
<artifactId>brewlet-maven-plugin</artifactId>
<version>0.4.0</version>
<version>0.5.0</version>
<configuration>
<dependencyBundleImage>registry.example.com/platform/java-deps/spring-web:2026.08</dependencyBundleImage>
<sourceBom>com.example.platform:approved-spring-bom:2026.08</sourceBom>
Expand Down Expand Up @@ -130,7 +130,7 @@ owned by the application team.
<plugin>
<groupId>sh.brewlet</groupId>
<artifactId>brewlet-maven-plugin</artifactId>
<version>0.4.0</version>
<version>0.5.0</version>
<configuration>
<image>registry.example.com/apps/orders:${project.version}</image>
<dependencyBundle>registry.example.com/platform/java-deps/spring-web:2026.08</dependencyBundle>
Expand Down
2 changes: 1 addition & 1 deletion docs/runtime-metrics.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ Install or upgrade Brewlet with the values file:

```bash
helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \
--version 0.4.0 \
--version 0.5.0 \
--values metrics-values.yaml \
--set provisioner.pools="{java-workers}"
```
Expand Down
2 changes: 1 addition & 1 deletion docs/workshops/developers.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ Ask the Ops participant for:
export BREWLET_CONTEXT="<kubernetes-context>"
export BREWLET_NAMESPACE="<developer-namespace>"
export BREWLET_JDK="21"
export BREWLET_VERSION="0.4.0"
export BREWLET_VERSION="0.5.0"
export BREWLET_REGISTRY="<registry-host>/<team>"
```

Expand Down
2 changes: 1 addition & 1 deletion docs/workshops/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ The Ops workshop installs the released chart and CLI directly. The Dev workshop
uses the example application from the matching release tag:

```bash
git clone --depth 1 --branch v0.4.0 https://github.com/microsoft/brewlet.git
git clone --depth 1 --branch v0.5.0 https://github.com/microsoft/brewlet.git
cd brewlet
```

Expand Down
4 changes: 2 additions & 2 deletions docs/workshops/operations.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ Do not use a production or shared cluster for this preproduction workshop.
Set the Brewlet release and application registry used by both workshop parts:

```bash
export BREWLET_VERSION="0.4.0"
export BREWLET_VERSION="0.5.0"
export BREWLET_REGISTRY="<registry-host>/<team>"
```

Expand Down Expand Up @@ -168,7 +168,7 @@ Give the developer:
| Namespace | Namespace where the developer may deploy |
| RuntimeClass | `brewlet` |
| Supported JDK | `21` in this workshop |
| Brewlet version | `0.4.0` |
| Brewlet version | `0.5.0` |
| Registry prefix | Repository where the developer can push OCI images |
| Pull secret | Required only when the registry is private |

Expand Down
2 changes: 1 addition & 1 deletion kubernetes/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ documentation lives in [`docs/`](../docs/).

```bash
helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \
--version 0.4.0 \
--version 0.5.0 \
--namespace brewlet \
--create-namespace \
--set provisioner.pools="{java-workers}"
Expand Down
2 changes: 1 addition & 1 deletion kubernetes/charts/brewlet/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ runtime catalog. Name the node pool the privileged provisioner may modify:

```bash
helm upgrade --install brewlet oci://ghcr.io/microsoft/charts/brewlet \
--version 0.4.0 \
--version 0.5.0 \
--namespace brewlet \
--create-namespace \
--set provisioner.pools="{java-workers}" \
Expand Down
4 changes: 2 additions & 2 deletions scripts/verify-release-provenance.sh
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
#
# Consumers can run this against any published release:
#
# ./scripts/verify-release-provenance.sh 0.4.0
# ./scripts/verify-release-provenance.sh 0.5.0
#
# It is also the release smoke test: the release workflow runs it against the
# version it just published, so a release that fails to produce verifiable
Expand All @@ -23,7 +23,7 @@ IMAGES=(brewlet-operator brewlet-admission brewlet-node-provisioner)

usage() {
echo "usage: $0 <version>" >&2
echo " version: release version without the v prefix, e.g. 0.4.0" >&2
echo " version: release version without the v prefix, e.g. 0.5.0" >&2
}

version="${1:-}"
Expand Down
2 changes: 1 addition & 1 deletion site/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -77,7 +77,7 @@ Before publishing installation guidance, run the same release smoke test as
the Pages workflow:

```bash
./site/scripts/verify-release-artifacts.sh 0.4.0
./site/scripts/verify-release-artifacts.sh 0.5.0
```

It requires `curl`, Maven, JDK 21+, Helm, Docker CLI, and an authenticated
Expand Down
12 changes: 6 additions & 6 deletions site/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -123,7 +123,7 @@ <h2 data-reveal>Ship the JAR, not the runtime</h2>
$ brewlet push target/app.jar demo/app:1.4.2 --store ./oci --format image

<span class="c-cm"># Publish with the released plugin installed in the quick start below:</span>
$ mvn package sh.brewlet:brewlet-maven-plugin:0.4.0:push \
$ mvn package sh.brewlet:brewlet-maven-plugin:0.5.0:push \
<span class="c-key">-Dbrewlet.image</span>=registry.example.com/team/app:1.4.2

<span class="c-cm"># Deploy it — one Brewlet-specific line.</span>
Expand Down Expand Up @@ -408,7 +408,7 @@ <h2 data-reveal>Try Brewlet locally</h2>
<div class="code-card wide" data-reveal>
<div class="code-head"><span class="dot red"></span><span class="dot amber"></span><span class="dot green"></span><span class="code-title">terminal</span></div>
<pre><code><span class="c-cm"># Install the CLI (the installer verifies the release checksum)</span>
$ export BREWLET_VERSION="0.4.0"
$ export BREWLET_VERSION="0.5.0"
$ curl -fsSL https://brewlet.sh/install.sh | sh
$ export PATH="$HOME/.local/bin:$PATH"
$ brewlet version
Expand All @@ -420,9 +420,9 @@ <h2 data-reveal>Try Brewlet locally</h2>

<span class="c-cm"># Package, inspect, and run from a local OCI store</span>
$ brewlet push integration-tests/fixtures/demo-app/target/app.jar \
demo/hello:0.4.0 --store ./oci --format artifact
$ brewlet inspect demo/hello:0.4.0 --store ./oci
$ brewlet run demo/hello:0.4.0 --store ./oci</code></pre>
demo/hello:0.5.0 --store ./oci --format artifact
$ brewlet inspect demo/hello:0.5.0 --store ./oci
$ brewlet run demo/hello:0.5.0 --store ./oci</code></pre>
</div>
<p class="section-lede" data-reveal>Stop the app with Ctrl+C, then install the released Maven plugin to package a local image. See <a href="/docs/installation/#verify-a-release">release verification</a> for checksums and build provenance. Use the plugin's <code>push</code> goal with a registry you control when you are ready to publish.</p>
<div class="code-card wide" data-reveal>
Expand All @@ -437,7 +437,7 @@ <h2 data-reveal>Try Brewlet locally</h2>
<span class="c-cm"># Build a local OCI layout for the example app</span>
$ mvn -f integration-tests/fixtures/demo-app/pom.xml package \
"sh.brewlet:brewlet-maven-plugin:${BREWLET_VERSION}:build" \
<span class="c-key">-Dbrewlet.image</span>=demo/hello:0.4.0</code></pre>
<span class="c-key">-Dbrewlet.image</span>=demo/hello:0.5.0</code></pre>
</div>
<div class="hero-cta center">
<a class="btn btn-primary" href="/docs/getting-started/">Open the full quick start</a>
Expand Down
2 changes: 1 addition & 1 deletion site/scripts/test_release_artifacts.py
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@

ROOT = Path(__file__).resolve().parents[2]
DIGEST = "0123456789abcdef" * 4
VERSION = "0.4.0"
VERSION = "0.5.0"

# Transport/workload stand-ins fail on unrecognized commands. Helm still
# reads/renders the actual packaged chart, with synthetic release image pins.
Expand Down
4 changes: 2 additions & 2 deletions site/scripts/test_site_contracts.py
Original file line number Diff line number Diff line change
Expand Up @@ -119,7 +119,7 @@ def test_cli_examples_explicitly_use_local_stores(self):

def test_quickstart_uses_released_cli_plugin_and_matching_example_source(self):
blocks = "\n".join(block for section, block in self.page.blocks if section == "quickstart")
self.assertIn('export BREWLET_VERSION="0.4.0"', blocks)
self.assertIn('export BREWLET_VERSION="0.5.0"', blocks)
self.assertIn("curl -fsSL https://brewlet.sh/install.sh | sh", blocks)
self.assertLess(blocks.index("export BREWLET_VERSION"), blocks.index("install.sh"))
self.assertIn('export PATH="$HOME/.local/bin:$PATH"', blocks)
Expand All @@ -143,7 +143,7 @@ def test_documented_quickstarts_use_the_release_installer_by_default(self):
with self.subTest(document=filename):
document = (ROOT / filename).read_text(encoding="utf-8")
primary_path = document.split("### Alternative: build from source")[0]
self.assertIn('export BREWLET_VERSION="0.4.0"', primary_path)
self.assertIn('export BREWLET_VERSION="0.5.0"', primary_path)
self.assertIn("curl -fsSL https://brewlet.sh/install.sh | sh", primary_path)
self.assertLess(primary_path.index("export BREWLET_VERSION"),
primary_path.index("install.sh"))
Expand Down
2 changes: 1 addition & 1 deletion site/scripts/verify-release-artifacts.sh
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

set -euo pipefail

version="${1:-0.4.0}"
version="${1:-0.5.0}"
# Releases from this version on publish build provenance and a digest-pinned
# chart. Older releases predate that workflow and are verified by checksum only.
# Keep this at or below the version the Pages workflow verifies, otherwise
Expand Down
Loading
Loading